Home › HRMS › Job roles › Information Technology › Security Architect
Information Technology · Senior management

Security Architect job description

A Security Architect designs the security controls built into a company's applications, networks and cloud platforms. They decide how identity, access, encryption, logging and network segmentation should work, review new designs for risk before they are built, and map controls to ISO 27001, client contracts and regulator guidelines. In Indian IT firms, banks, fintechs and BPOs the role usually reports to the CISO. A good Security Architect makes the secure option the easy option for engineers and reduces audit findings year after year.

DetailFor this role
DepartmentInformation Technology
LevelSenior management
Reports toChief Information Security Officer
Direct reportsNone
Experience10 to 15 years in IT security, with 4 or more years designing security for applications and cloud platforms

Security Architect job description template

Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.

Job title: Security Architect

Department: Information Technology

Reports to: Chief Information Security Officer

Location: [City], [office, branch or site]

About the role

A Security Architect designs the security controls built into a company's applications, networks and cloud platforms. They decide how identity, access, encryption, logging and network segmentation should work, review new designs for risk before they are built, and map controls to ISO 27001, client contracts and regulator guidelines. In Indian IT firms, banks, fintechs and BPOs the role usually reports to the CISO. A good Security Architect makes the secure option the easy option for engineers and reduces audit findings year after year.

Key responsibilities

  • Define the security reference architecture for identity, network segmentation, encryption, key management, logging and endpoint protection.
  • Run threat modelling sessions for new applications and major changes, and record each risk with its agreed mitigation.
  • Review solution and cloud designs before build, and approve them, send them back or record risk acceptance by a named business owner.
  • Design identity and access controls, including single sign-on, multi-factor authentication, privileged access and joiner, mover and leaver flows.
  • Set standards for encryption at rest and in transit, secrets management, certificate lifecycle and key rotation.
  • Build security checks into delivery pipelines with SAST, DAST, dependency and container image scanning, and agree fail rules with engineering.
  • Map controls to ISO 27001, SOC 2, PCI DSS or RBI and SEBI guidelines where they apply, and give auditors the evidence they ask for.
  • Assess third-party products and SaaS vendors before purchase, including where data is stored and who can access it.
  • Specify logging and monitoring requirements so the SOC receives the events it needs to detect attacks.
  • Review penetration test and red team results, and turn repeat findings into architecture fixes rather than one-off patches.

Requirements

  • B.E. or B.Tech in Computer Science, IT or Electronics
  • CISSP, CISM or CCSP certification
  • SABSA or AWS Security Specialty certification is an advantage
  • 10 to 15 years in IT security, with 4 or more years designing security for applications and cloud platforms

KRAs and KPIs for a Security Architect

Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.

Key result areaHow to measure it
Design reviewsEvery new internet-facing application reviewed before go-live, with reviews completed within 5 working days
Vulnerability closureCritical and high penetration test findings closed within 30 days, with no repeat finding in the next test
Identity controlsMulti-factor authentication enforced for all remote, admin and cloud console access
Audit outcomesNo major non-conformity in ISO 27001 surveillance audits or client security audits
Pipeline securitySecurity scanning active in the pipelines of all production applications, with fail rules agreed
Vendor riskSecurity assessment done for every new vendor handling company or client data before the contract is signed

Skills and tools

Security architecture frameworksThreat modelling with STRIDEIdentity and access managementCloud security on AWS or AzureNetwork segmentation and zero trustCryptography and key managementISO 27001 and SOC 2 controlsApplication security testingExplaining risk to business ownersFirm but practical judgement

Tools used day to day: Burp Suite, SonarQube or Checkmarx, Microsoft Entra ID or Okta, HashiCorp Vault or AWS KMS, Splunk or Microsoft Sentinel, Palo Alto or Fortinet firewalls, Microsoft Threat Modeling Tool.

Reporting line and career path

Chief InformationSecurity OfficerSecurity Architect

Interview questions for a Security Architect

  1. Walk me through a threat model you built for an application that holds customer payment data.
  2. An engineering team wants to keep API keys in environment variables. What do you recommend and why?
  3. How would you give vendor support engineers production access twice a month without standing privileges?
  4. A business head insists on launching with a known high-risk finding. How do you handle it?
  5. What changes from a security view when an application moves from the data centre to a public cloud?
  6. How do you stop security reviews from becoming a bottleneck for delivery teams?

Managing a Security Architect in ZeniaHR

Hire and manage your information technology team in one place

Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What does a security architect do?

A security architect designs how security works across a company's systems: identity and access, encryption, network segmentation, logging and secure development. They review new designs for risk, set security standards, guide engineers on fixes and help the company pass ISO 27001 and client audits. The aim is to prevent problems at the design stage instead of chasing them after launch.

What is the difference between a security architect and a security analyst?

A security analyst monitors alerts, investigates incidents and runs vulnerability scans day to day. A security architect designs the controls those analysts depend on and decides how new systems should be protected before they are built. Analysts are often early or mid-career, while architects usually have ten or more years in security.

Which certifications are best for a security architect?

CISSP is the certification Indian employers ask for most often, followed by CISM for governance-heavy roles and CCSP or AWS Security Specialty for cloud-focused roles. SABSA is specific to security architecture and is valued by banks and large enterprises. Interviews still focus most on design work you have actually done.